Index | Thread | Search

From:
Rafael Sadowski <rafael@sizeofvoid.org>
Subject:
Re: NEW: security/cosign
To:
ports@openbsd.org
Date:
Tue, 4 Aug 2026 17:15:14 +0200

Download raw body.

Thread
  • Rafael Sadowski:

    NEW: security/cosign

    • Rafael Sadowski:

      NEW: security/cosign

On Tue Aug 04, 2026 at 05:04:46PM +0200, Rafael Sadowski wrote:
> OK to import cosign-3.1.2?
> 
> Comment:
> sigstore signing tool
> 
> Description:
> Signing OCI containers (and other artifacts) using Sigstore.
> 
> Cosign supports:
> 
> - "Keyless signing" with the Sigstore public good Fulcio certificate authority
>   and Rekor transparency log (default)
> - Hardware and KMS signing
> - Signing with a cosign generated encrypted private/public keypair
> - Container Signing, Verification and Storage in an OCI registry
> - Bring-your-own PKI
> 
> Maintainer: Rafael Sadowski <rsadowski@openbsd.org>
> 
> WWW: https://www.sigstore.dev/
> 
> 

Now with attachment, submitting new ports does involve this extra task ;)